Privacy Policy
Template for review by your counsel before launch. Replace every {placeholder}.
This Privacy Policy explains how Shashi Kumar, an individual operating Sentinel as a sole proprietor based in Bangalore, India (“Sentinel”, “we”, “us”) collects, uses, shares, and protects personal data when you use our website and the Sentinel service (the “Service”). It applies to visitors, account holders, and the authorized users of our customers.
1. Who we are & our role
For your account and website data, we act as a data controller. For data we process on behalf of a customer to provide the Service (e.g. AI inventory and findings), the customer is the controller and we are a data processor, processing only on the customer's instructions under our agreement and the Data Processing Addendum.
2. Information we collect
- Account data: name, work email, organization name, and a securely hashed password.
- Service data: the AI inventory, findings, policies, audit records, and actor records generated when you use the Service. We do not collect AI prompts/responses or your document contents. With local sensor mode, your raw logs never leave your environment.
- Billing data: plan and a payment reference. Card details are handled by our payment processor; we never see or store them.
- Usage & device data: log data such as IP address, browser type, pages viewed, and timestamps, used for security and to operate the Service.
- Communications: messages you send us (support, sales, security reports).
3. How we use information
- To provide, secure, maintain, and improve the Service.
- To authenticate you and prevent fraud and abuse.
- To process payments and manage subscriptions.
- To communicate about your account, security, and service changes.
- To comply with legal obligations and enforce our terms.
We do not sell personal data, and we do not use customer data to train AI models.
4. Legal bases (GDPR) and DPDP Act
Where GDPR applies, we rely on: performance of a contract (to provide the Service), legitimate interests (security, service improvement), consent (where required, e.g. certain cookies/marketing), and legal obligation. Under India's Digital Personal Data Protection Act, 2023, we process personal data for the specified, lawful purposes above, on the basis of consent or as otherwise permitted by law.
5. Sharing & sub-processors
We share data only with service providers who help us run the Service, under contract and confidentiality:
- Hosting & storage — Hetzner Cloud (EU)
- Payments — Razorpay / Stripe
- Transactional email — Cloudflare Email Routing
- Backups — Cloudflare R2
We may also disclose data to comply with law or to protect rights and safety. We do not otherwise share personal data with third parties.
6. International transfers
We can host your data in a region you choose (e.g. India or the EU). Where data is transferred across borders, we use appropriate safeguards (such as Standard Contractual Clauses) as required by applicable law.
7. Data retention
We retain personal data for as long as your account is active or as needed to provide the Service, and thereafter as required for legal, accounting, or security purposes. On a verified deletion request or account closure, we delete your organization's data — including from backups on the next rotation cycle — typically within 30 days. Demo/sandbox data auto-expires.
8. Security
We protect data with tenant isolation, encryption in transit and at rest, scrypt-hashed passwords, hashed API keys, a tamper-evident audit log, and a zero-dependency, auditable codebase. See our Trust & Security page for details. No method is perfectly secure, but we work hard to protect your data and disclose our current limitations honestly.
9. Your rights
Subject to applicable law (GDPR, DPDP, and others), you may request to access, correct, delete, export, or restrict processing of your personal data, and to object or withdraw consent. Where we process data on behalf of a customer, please direct requests to that customer (the controller); we will assist them. To exercise rights with us directly, contact privacy@sentinelops.in. You also have the right to complain to a supervisory authority or the Data Protection Board of India.
10. Cookies
We use only strictly necessary cookies (for example, your authenticated session and your theme preference). We do not use advertising cookies. Because session cookies are essential to operate the Service, they cannot be disabled while using your account.
11. Children
The Service is for businesses and is not directed to children under 18 (or the age of majority in your jurisdiction). We do not knowingly collect their data.
12. Changes
We may update this policy; we will post the new version here and update the date above, and notify you of material changes.
13. Contact & Grievance Officer
Sentinel is operated by Shashi Kumar (sole proprietor), Bangalore, Karnataka, India. Privacy & data protection: privacy@sentinelops.in. Grievance Officer (India DPDP): Shashi Kumar — hello@sentinelops.in, +91 97691 99205. We aim to respond within 30 days.